Not of the host system, assuming we're talking about a compromised VM, running as a non-root user.

I assume you mean container, not VM. But yes, container makes it harder.